The FBI is issuing a warning regarding the Kali365 phishing-as-a-service platform (PhaaS), which uses OAuth device code authentication abuse to steal session tokens and get around multi-factor authentication (MFA) in order to take over Microsoft 365 accounts.
The FBI PSA claims that Kali365 first surfaced in April 2026 and is disseminated through Telegram channels to hackers looking for a simpler method of breaking into Microsoft 365 accounts without stealing passwords or intercepting MFA codes.
In order to obtain access to Microsoft Entra and Microsoft 365 accounts, the platform employs device code phishing, a growing technique that takes advantage of Microsoft’s valid OAuth 2.0 Device Authorization grant route.
In order to enable devices with limited input capabilities—like smart TVs, conference room systems, streaming devices, printers, and Internet of Things devices—to authenticate via another device using a short code read more about FBI warns of Kali365 phishing service targeting Microsoft 365 accounts.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
